Daily briefing · July 14, 2026

CRITICAL: Four CVEs Under Active Exploitation — SMA1000 SSRF, AD FS Privilege Escalation, and SharePoint Auth Bypass Lead the Charge

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — critical

July 14, 2026 delivers a CRITICAL verdict: four vulnerabilities confirmed in active exploitation by both CISA KEV and VulnCheck, spanning SonicWall SMA1000, Windows Active Directory Federation Services, and Microsoft SharePoint. With 990 new CVEs published today — 65 of them critical — and three CVSS 10.0 severities outside the KEV list still demanding immediate attention, defenders are facing one of the heavier single-day loads of the year.

Today’s brief
  • 4 CVEs in active exploitation (CISA KEV + VulnCheck confirmed): SMA1000 SSRF, AD FS privilege escalation, SMA1000 code injection, and SharePoint auth bypass.
  • Three additional CVSS 10.0 vulnerabilities published today: JWT algorithm bypass in Opcenter X, unauthenticated debug port in Rockwell 1715 EtherNet/IP, and auth bypass in JetBrains YouTrack.
  • LockBit5 ransomware hits Brazilian public sector: Mato Grosso state health portal (saude.mt.gov.br) and two business services firms among freshly confirmed victims.
  • 990 new CVEs today, 65 critical — patch prioritization is essential; focus immediately on KEV items and internet-exposed appliances.
65
critical
4
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-15409KEVCVSS 10affects SMA1000
A CVSS 10.0 SSRF vulnerability in SonicWall SMA1000's Work Place interface allows an unauthenticated remote attacker to force the appliance to make arbitrary outbound requests — actively exploited in the wild per CISA KEV and VulnCheck. Internet-exposed SMA1000 appliances should be treated as critically compromised until patched.
2
CVE-2026-56155KEVHIGH 7.8affects Windows 10 Version 1607
An Active Directory Federation Services (AD FS) privilege escalation flaw — confirmed in active exploitation — allows an already-authorized attacker to elevate local privileges, making it a critical post-compromise multiplier in Windows environments running AD FS. Organizations relying on AD FS for identity federation should apply the patch immediately and audit privilege escalation telemetry.
3
CVE-2026-15410KEVHIGH 7.2affects SMA1000
A post-authentication code injection vulnerability in SonicWall SMA1000's Appliance Management Console (AMC) enables a remote admin-level attacker to execute arbitrary OS commands — confirmed actively exploited. Combined with CVE-2026-15409, this creates a dangerous chained attack path from unauthenticated SSRF to full OS-level compromise on SMA1000 devices.
4
CVE-2026-56164KEVMEDIUM 5.3affects Microsoft SharePoint Enterprise Server 2016
A missing authentication flaw in Microsoft SharePoint Enterprise Server 2016 allows unauthenticated network attackers to elevate privileges — actively exploited, despite its moderate CVSS 5.3 score. The low score belies the real danger: unauthenticated privilege escalation on SharePoint servers can pivot to lateral movement across enterprise environments.
5
CVE-2026-56451CVSS 10affects Opcenter X
A CVSS 10.0 JWT algorithm validation failure in Siemens Opcenter X allows any unauthenticated attacker to forge arbitrary tokens and impersonate any user, including administrators, granting full platform access. Although EPSS registers at 0% today, the trivial exploitability of JWT algorithm confusion attacks means weaponization could come quickly.
6
CVE-2026-10577CVSS 10affects 1715 EtherNet/IP Communications Module
Rockwell Automation's 1715-AENTR EtherNet/IP Communications Module exposes an unauthenticated, network-accessible debug CLI with no privilege controls — CVSS 10.0. An attacker can read or delete files, halt tasks, modify memory, and alter I/O states, posing a direct threat to operational technology (OT) and industrial control environments.
7
CVE-2026-62422CVSS 10affects YouTrack
JetBrains YouTrack is affected by a CVSS 10.0 authentication bypass via direct database access, enabling any attacker to obtain administrative access across multiple product versions. Development and project management platforms like YouTrack often hold sensitive source code references and internal communications — compromise carries significant supply chain risk.
8
CVE-2026-48318CVSS 9.9affects ColdFusion 2023
Adobe ColdFusion 2023 is vulnerable to a path traversal flaw (CVSS 9.9) that allows arbitrary file system reads without user interaction, potentially exposing configuration files, credentials, and application secrets. ColdFusion servers are historically high-value targets and have seen repeated exploitation campaigns; this requires urgent patching.
9
CVE-2026-57092CVSS 9.9affects Windows 10 Version 1607
A use-after-free in Windows VMSwitch (CVSS 9.9) allows an authorized attacker to elevate privileges over a network, making it a serious risk in virtualized Windows environments and Hyper-V deployments. Privilege escalation at the virtual switch layer can affect multiple guest VMs simultaneously, amplifying the blast radius.
10
CVE-2026-15043CVSS 9.8affects DBI::SQL::Nano
DBI::SQL::Nano (Perl) versions 1.42 through before 1.651 evaluate SQL WHERE predicates with inverted comparison operators, meaning queries using <= and >= on text fields return incorrect results — with potential security implications for applications relying on DBI's built-in SQL engine for access control decisions. Developers using SQL::Nano as a fallback query engine should validate all comparison-based filtering logic and upgrade immediately.
Ransomware today

LockBit5 is the dominant threat in recent activity, with confirmed victims including santoinacio-rio.com.br and lbreng.com.br (both Business Services) and notably saude.mt.gov.br, the public health portal of Mato Grosso state, signaling continued pressure on Brazilian public sector infrastructure. Over the past 30 days, lockbit3, ransomhub, lockbit5, thegentlemen, 8base, and arcusmedia have been the six most active ransomware groups, all with significant focus on Brazilian targets.

santoinacio-rio.com.br BRlockbit5 · Business Services
lbreng.com.br BRlockbit5 · Business Services
saude.mt.gov.br BRlockbit5 · Public Sector
lockbit3 39ransomhub 35lockbit5 29thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actors are currently flagged as active or updated in threat intelligence feeds: apt73, BlackShadow (Iran-linked), CoinbaseCartel, CopyKittens (Iran-linked), DragonForce, and AgainstTheWest. While no confirmed victim attributions are recorded for these groups in the current window, their active status warrants heightened monitoring, particularly for organizations in sectors historically targeted by Iranian APT clusters.

Brazil focus

Brazil is facing a concentrated ransomware wave: in recent weeks, LockBit5 claimed saude.mt.gov.br (Mato Grosso public health), santoinacio-rio.com.br, and lbreng.com.br; Deadlock targeted manufacturers Bombas Ideal and Werken Química Brasil S.A., as well as Direção Estacionamentos S.A.; Qilin claimed S.J. Louis; and Doommageddon targeted Francisco Imóveis. The breadth of sectors — public health, manufacturing, consumer services, and real estate — underscores that no vertical is out of scope for ransomware actors operating against Brazilian organizations.

santoinacio-rio.com.brlockbit5 · Business Services
saude.mt.gov.brlockbit5 · Public Sector
lbreng.com.brlockbit5 · Business Services
Bombas IdealDeadlock · Manufacturing
Werken Química Brasil S.A.Deadlock · Manufacturing
Direção Estacionamentos S.A.Deadlock · Consumer Services
S.J. Louisqilin
Francisco ImóveisDoommageddon · Consumer Services
Today’s recommendation: Immediately isolate and patch all internet-exposed SonicWall SMA1000 appliances (CVE-2026-15409 and CVE-2026-15410), apply Microsoft's AD FS and SharePoint patches (CVE-2026-56155 and CVE-2026-56164), and audit all Rockwell 1715-AENTR devices for unauthorized network access to their debug interfaces. For OT and ICS environments, network segmentation and access controls on the EtherNet/IP module should be validated as an immediate compensating control if patching cannot happen instantly.
With four actively exploited vulnerabilities and six additional critical-severity flaws published in a single day, now is the moment to validate whether your external attack surface and internal segmentation controls would contain — or silently allow — the threats described today.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →